ai-rag-pipeline

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its RAG purpose, but it relies on a third-party platform CLI, routes data through inference.sh-managed apps, and instructs transitive skill installation. This looks like a coherent platform integration rather than confirmed malware, but the supply-chain, external-content, and delegated-trust risks are significant enough to treat it as medium risk.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Mar 27, 2026, 02:29 PM
Package URL
pkg:socket/skills-sh/inference-sh-8%2Fskills%2Fai-rag-pipeline%2F@3be4496ccafb71335ce5010e43f93ae314c9d5da